Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
On a fully updated Windows 11 computer, Windows Plug and Play can be exploited to retrieve signed vendor software for an emulated USB device and run privileged installation components that researchers tied to SYSTEM access.
When compatible Plug and Play or low-level USB redirection is enabled, the same PnP path can be initiated via Remote Desktop without the need for actual hardware; Microsoft claims that redirection is not permitted by default.
In "Plug And Pwn: Weaponizing Windows PnP Auto-Install," a study prepared for DEF CON 34, security experts Alejandro Hernando and Borja Martinez detailed the method.
They developed tools to simulate any USB device and claimed that an unauthorized user could convert the PnP installation path into SYSTEM code execution under certain circums...






